Our client, a well established financial services organisation, is continuing its cyber security and operational resilience uplift program, aligned to APRA CPS 230 and CPS 234, and benchmarked against NIST and ISO/IEC 27001. As the business moves through third-party risk remediation and control maturity assessment, the team needs additional hands-on cyber GRC capability to maintain momentum.
This is a contract role suited to someone who has worked on a live regulatory or standards aligned cyber uplift program (CPS 230, CPS 234, NIST CSF, or ISO 27001) and can hit the ground running.
What you'll be doing
- Assessing and uplifting security controls against ISO/IEC 27001 and the NIST CSF functions.
- Supporting third-party/material service provider risk assessments, including security due diligence and control testing
- Mapping critical operations and technology assets against control frameworks and identifying gaps
- Conducting control testing, evidence collection, and maturity assessments ahead of internal and external audits
- Contributing to ISMS documentation, policies, standards, risk treatment plans, Statements of Applicability
- Liaising with security engineering, risk, audit, and vendor management stakeholders to close out findings
What we're looking for
- Proven experience in a cyber security GRC or information security role within financial services or other highly regulated industries.
- Working knowledge of NIST CSF and ISO/IEC 27001 (certification such as ISO 27001 Lead Auditor/Implementer highly regarded)
- Exposure to APRA CPS 230/CPS 234 or comparable regulatory frameworks
- Comfortable running control assessments and translating technical findings into risk language for stakeholders
- Contract background strongly preferred, available to start on short notice, based in Melbourne
What's on offer
- Competitive day rate, negotiable based on experience
- Hybrid working arrangement, Melbourne CBD
- High-profile program with genuine extension/renewal potential
- Exposure to a live, well-resourced cyber security transformation program benchmarked against leading frameworks